SecurityFocus Linux Newsletter #427

[email protected] Thu, 19 Feb 2009 16:43:08 -0700
Newsgroups gmane.comp.security.news.linux
Message-ID <[email protected]>
SecurityFocus Linux Newsletter #427
----------------------------------------

This issue is sponsored by Purewire

NEW! White Paper: "Hackers Announce Open Season on Web 2.0 Users and Brow=
sers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's. Download t=
his white paper now to mitigate your online security risks.
=20
http://www.purewire.com/lp/sec/


SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs

------------------------------------------------------------------
I.   FRONT AND CENTER
       1. Free Market Filtering
       2. Don't Blame the Browser
II.  LINUX VULNERABILITY SUMMARY
       1. Trend Micro InterScan Web Security Suite Multiple Security Bypa=
ss Vulnerabilities
       2. Trend Micro Interscan Web Security HTTP Proxy Authentication In=
formation Disclosure Vulnerability
       3. ZeroShell 'cgi-bin/kerbynet' Remote Command Execution Vulnerabi=
lity
       4. TYPO3 Cross Site Scripting and Information Disclosure Vulnerabi=
lities
       5. GNOME Evolution S/MIME Email Signature Verification Vulnerabili=
ty
       6. ProFTPD 'mod_sql' Username SQL Injection Vulnerability
       7. libvirt 'libvirt_proxy.c' Local Privilege Escalation Vulnerabil=
ity
       8. pam-krb5 Local Privilege Escalation Vulnerability
       9. pam-krb5 'KRB5CCNAME' Environment Variable Local Privilege Esca=
lation Vulnerability
       10. Net-SNMP 'snmpUDPDomain.c' Remote Information Disclosure Vulne=
rability
       11. Linux Kernel Kprobe Memory Corruption Vulnerability
       12. SUSE blinux Buffer Overflow Vulnerability
       13. Ubuntu xorg-driver-fglrx 'LD_LIBRARY_PATH' Remote Command Exec=
ution Vulnerability
       14. Yaws Multiple Header Request Denial of Service Vulnerability
III. LINUX FOCUS LIST SUMMARY
       1. CanSecWest 2009 Speakers and Dojo courses (Mar 14-20)
       2. DEFCON 17 CFP now open
IV.  UNSUBSCRIBE INSTRUCTIONS
V.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1.Free Market Filtering
By Mark Rasch
The Australian government is considering requiring that Internet service =
providers in that country install filters which would prevent citizens fr=
om accessing tens of thousands of sites that contain "objectionable" mate=
rial.=20
http://www.securityfocus.com/columnists/493

2.Don't Blame the Browser
Melih Abdulhayoglu
There was a time when most diseases were fatal for humans. Intense study =
and research helped doctors manage diseases better, and subsequently even=
 prevent them altogether.=20
http://www.securityfocus.com/columnists/492


II.  LINUX VULNERABILITY SUMMARY
------------------------------------
1. Trend Micro InterScan Web Security Suite Multiple Security Bypass Vuln=
erabilities
BugTraq ID: 33679
Remote: Yes
Date Published: 2009-02-09
Relevant URL: http://www.securityfocus.com/bid/33679
Summary:
Trend Micro InterScan Web Security Suite is prone to multiple security-by=
pass vulnerabilities.

Successful exploits may allow attackers to access sensitive areas and to =
elevate privileges to perform certain restricted actions, such as modifyi=
ng system configuration.

 These issues affect InterScan Web Security Suite 3.1 for Windows. Report=
edly, Linux versions of the application are also affected.

2. Trend Micro Interscan Web Security HTTP Proxy Authentication Informati=
on Disclosure Vulnerability
BugTraq ID: 33687
Remote: Yes
Date Published: 2009-02-09
Relevant URL: http://www.securityfocus.com/bid/33687
Summary:
Trend Micro Interscan Web Security Suite is prone to an information-discl=
osure vulnerability when handling HTTP Proxy-Authentication headers.=20

An attacker can exploit this issue to obtain sensitive information that m=
ay lead to further attacks.

3. ZeroShell 'cgi-bin/kerbynet' Remote Command Execution Vulnerability
BugTraq ID: 33702
Remote: Yes
Date Published: 2009-02-09
Relevant URL: http://www.securityfocus.com/bid/33702
Summary:
ZeroShell is prone to a vulnerability that attackers can leverage to exec=
ute arbitrary commands. This issue occurs because the software fails to a=
dequately sanitize user-supplied input.

Successful attacks can compromise the affected application and possibly t=
he underlying computer.

ZeroShell 1.0beta11 is vulnerable; other versions may also be affected.

4. TYPO3 Cross Site Scripting and Information Disclosure Vulnerabilities
BugTraq ID: 33714
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33714
Summary:
TYPO3 is prone to multiple cross-site scripting vulnerabilities and an in=
formation-disclosure vulnerability.

An attacker may leverage these issues to execute arbitrary script code in=
 the browser of an unsuspecting user in the context of the affected site,=
 steal cookie-based authentication credentials, and obtain sensitive info=
rmation.

5. GNOME Evolution S/MIME Email Signature Verification Vulnerability
BugTraq ID: 33720
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33720
Summary:
GNOME Evolution is prone to a signature-verification vulnerability.=20

Attackers can exploit this issue through man-in-the-middle attacks to mod=
ify signed messages undetected.

6. ProFTPD 'mod_sql' Username SQL Injection Vulnerability
BugTraq ID: 33722
Remote: Yes
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33722
Summary:
ProFTPD is prone to an SQL-injection vulnerability because it fails to su=
fficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to manipulate SQL queries, =
modify data, or exploit latent vulnerabilities in the underlying database=
. This may result in unauthorized access and a compromise of the applicat=
ion; other attacks are also possible.

ProFTPD 1.3.1 through 1.3.2 rc 2 are vulnerable.

7. libvirt 'libvirt_proxy.c' Local Privilege Escalation Vulnerability
BugTraq ID: 33724
Remote: No
Date Published: 2009-02-10
Relevant URL: http://www.securityfocus.com/bid/33724
Summary:
The 'libvirt' library is prone to a local privilege-escalation vulnerabil=
ity because it fails perform adequate boundary checks on user-supplied da=
ta.=20

Local attackers can exploit this issue to execute arbitrary code with sup=
eruser privileges. Successfully exploiting this issue will result in the =
complete compromise of affected computers. Failed exploit attempts will r=
esult in a denial-of-service condition.

The issue affects libvirt 0.5.1; other versions may also be affected.

8. pam-krb5 Local Privilege Escalation Vulnerability
BugTraq ID: 33740
Remote: No
Date Published: 2009-02-11
Relevant URL: http://www.securityfocus.com/bid/33740
Summary:
The 'pam-krb5' library is prone to a local privilege-escalation vulnerabi=
lity because it fails to properly handle setuid processes.

Local attackers may exploit this issue to gain elevated privileges, which=
 may lead to a complete compromise of the system.

This issue affects pam-krb5 as shipped with Debian, Ubuntu, and Gentoo Li=
nux releases; other versions may also be vulnerable.

9. pam-krb5 'KRB5CCNAME' Environment Variable Local Privilege Escalation =
Vulnerability
BugTraq ID: 33741
Remote: No
Date Published: 2009-02-11
Relevant URL: http://www.securityfocus.com/bid/33741
Summary:
The 'pam-krb5' library is prone to a local privilege-escalation vulnerabi=
lity because it fails to properly handle setuid processes.

A local attacker may exploit this to corrupt the credential cache. This m=
ay allow the attacker to gain elevated privileges or to create a denial-o=
f-service condition.

Versions prior to pam-krb5 3.13 are vulnerable.

10. Net-SNMP 'snmpUDPDomain.c' Remote Information Disclosure Vulnerabilit=
y
BugTraq ID: 33755
Remote: Yes
Date Published: 2009-02-12
Relevant URL: http://www.securityfocus.com/bid/33755
Summary:
Net-SNMP is prone to a remote information-disclosure vulnerability becaus=
e it fails to properly handle TCP Wrapper authorization rules.

Exploiting this issue will allow attackers to obtain sensitive informatio=
n that can help them further attacks.

Net-SNMP 5.4.2.1 is vulnerable; other versions are also likely affected.

11. Linux Kernel Kprobe Memory Corruption Vulnerability
BugTraq ID: 33758
Remote: No
Date Published: 2009-02-12
Relevant URL: http://www.securityfocus.com/bid/33758
Summary:
The Linux kernel is prone to a memory-corruption vulnerability  because o=
f a design flaw in the Kprobe system.

Local attackers could exploit this issue to cause denial-of-service condi=
tions and possibly to execute arbitrary code with kernel-level privileges=
, but this has not been confirmed.

Versions prior to Linux kernel 2.6.28.5 are vulnerable.

12. SUSE blinux Buffer Overflow Vulnerability
BugTraq ID: 33794
Remote: No
Date Published: 2009-02-17
Relevant URL: http://www.securityfocus.com/bid/33794
Summary:
The SUSE 'blinux' (sbl) package is prone to a buffer-overflow vulnerabili=
ty because it fails to perform adequate boundary checks on user-supplied =
data.=20

A local attacker can exploit this issue to execute arbitrary code as the =
affected process, possibly resulting in elevated privileges. Failed explo=
it attempts are likely to result in denial-of-service conditions.

13. Ubuntu xorg-driver-fglrx 'LD_LIBRARY_PATH' Remote Command Execution V=
ulnerability
BugTraq ID: 33801
Remote: Yes
Date Published: 2009-02-17
Relevant URL: http://www.securityfocus.com/bid/33801
Summary:
Ubuntu 'xorg-driver-fglrx' is prone to a remote command-execution vulnera=
bility.

An attacker could exploit this issue by enticing an unsuspecting victim t=
o run an application in a directory containing a malicious library file w=
ith a specific name. A successful exploit will allow arbitrary code to ru=
n within the privileges of the currently logged-in user.
=20
Ubuntu 8.10 is vulnerable.

14. Yaws Multiple Header Request Denial of Service Vulnerability
BugTraq ID: 33834
Remote: Yes
Date Published: 2009-02-19
Relevant URL: http://www.securityfocus.com/bid/33834
Summary:
Yaws is prone to a remote denial-of-service vulnerability because it fail=
s to handle infinite header requests.

Successfully exploiting this issue will allow attackers to cause the affe=
cted application to consume memory, eventually denying service to legitim=
ate users.

Versions prior to Yaws 1.80 are vulnerable.

III. LINUX FOCUS LIST SUMMARY
---------------------------------
1. CanSecWest 2009 Speakers and Dojo courses (Mar 14-20)
http://www.securityfocus.com/archive/91/500979

2. DEFCON 17 CFP now open
http://www.securityfocus.com/archive/91/500978

IV.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to linux-secnews-unsubscribe@securi=
tyfocus.com from the subscribed address. The contents of the subject or m=
essage body do not matter. You will receive a confirmation request messag=
e to which you will have to answer. Alternatively you can also visit http=
://www.securityfocus.com/newsletters and unsubscribe via the website.=20

If your email address has changed email [email protected] and a=
sk to be manually removed.

V.   SPONSOR INFORMATION
------------------------
This issue is sponsored by Purewire

NEW! White Paper: "Hackers Announce Open Season on Web 2.0 Users and Brow=
sers"

Learn how hackers are exploiting your employees Web surfing to gain entry=
 into your network. Drive-by Downloads, Click Jacking, AJAX, XSS and Brow=
ser vulns are just some of the nasty attack methods hackers are coming up=
 with and it's no longer good enough to block known bad URL's. Download t=
his white paper now to mitigate your online security risks.
=20
http://www.purewire.com/lp/sec/